{"id":31063,"date":"2018-11-27T14:15:00","date_gmt":"2018-11-27T14:15:00","guid":{"rendered":"https:\/\/fr.cryptonews.com\/?p=31063"},"modified":"2023-06-26T11:07:31","modified_gmt":"2023-06-26T11:07:31","slug":"bitcoin-wallet-vulnerability-discovered-2400","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/","title":{"rendered":"D\u00e9couverte d&#8217;une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin"},"content":{"rendered":"<p>Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source Bitcoin de <b>BitPay<\/b>, aurait &eacute;t&eacute; compromis, ce qui est potentiellement aussi le cas pour d&rsquo;autres portefeuilles.<\/p><figure><img decoding=\"async\" src=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg\" sizes=\"(min-width: 640px) 720px, 100vw\" srcset=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg 300w, https:\/\/cimg.co\/w\/articles-attachments\/2\/5bf\/d380458867.jpg 600w, https:\/\/cimg.co\/w\/articles-attachments\/3\/5bf\/d380458867.jpg 720w, https:\/\/cimg.co\/w\/articles-attachments\/4\/5bf\/d380458867.jpg 900w, https:\/\/cimg.co\/w\/articles-attachments\/0\/5bf\/d380458867.jpg 1254w\" alt=\"\" class=\"content-img\"><figcaption>Source: iStock\/NicoElNino<\/figcaption><\/figure><p>BitPay <a href=\"https:\/\/blog.bitpay.com\/npm-package-vulnerability-copay\/\" target=\"_blank\" rel=\"noopener\">a publi&eacute; un avis<\/a> indiquant que les versions de Copay 5.0.2 &agrave; 5.1.0 &eacute;taient affect&eacute;es par le code malveillant et que les utilisateurs disposant de ces versions devraient &eacute;viter d&rsquo;ex&eacute;cuter ou d&rsquo;ouvrir l&rsquo;application avant d&rsquo;avoir install&eacute; Copay version 5.2.0. <\/p><p>&ldquo;Notre &eacute;quipe continue d&rsquo;enqu&ecirc;ter sur ce probl&egrave;me et sur l&rsquo;ampleur de la vuln&eacute;rabilit&eacute;&rdquo;, indique le communiqu&eacute; officiel. &ldquo;&Agrave; l&#8217;heure actuelle, nous avons seulement confirm&eacute; que le code malveillant avait &eacute;t&eacute; d&eacute;ploy&eacute; sur les versions 5.0.2 &agrave; 5.1.0 de nos applications Copay et BitPay. Cependant, l&#8217;application BitPay n&rsquo;a pas &eacute;t&eacute; affect&eacute; par le code malveillant. Nous cherchons toujours &agrave; savoir si cette vuln&eacute;rabilit&eacute; du code a d&eacute;j&agrave; &eacute;t&eacute; exploit&eacute;e contre les utilisateurs de Copay&rdquo;.<\/p><p>Copay, le portefeuille affect&eacute;, repr&eacute;sente plus de 100 000 t&eacute;l&eacute;chargements sur Android, le nombre d&#8217;utilisateurs d&#8217;autres plateformes comme iOS ou Windows est quant &agrave; lui inconnu. Tous les autres portefeuilles utilisant ce module pourraient &eacute;galement &ecirc;tre concern&eacute;s, m&ecirc;me si, au moment de la r&eacute;daction, aucun d&#8217;entre eux ne s&#8217;est manifest&eacute;.<\/p><p>Le probl&egrave;me provient d&#8217;un utilisateur de GitHub qui s&#8217;est propos&eacute; de prendre en charge la biblioth&egrave;que (library) en question, d&#8217;injecter le logiciel malveillant et de le patcher pour &eacute;viter de se faire rep&eacute;rer. <\/p><p>L&#8217;utilisateur, connu uniquement sous le nom de &#8220;right9ctrl&#8221;, a repris la maintenance du module &agrave; son cr&eacute;ateur original, le d&eacute;veloppeur Dominic Tarr, qui a d&eacute;clar&eacute; qu&#8217;il n&#8217;y avait pas touch&eacute; depuis des ann&eacute;es. En r&eacute;sum&eacute;, le d&eacute;veloppeur a mis &agrave; jour le module avec un logiciel malveillant, puis l&#8217;a cach&eacute;, mais les nombreuses personnes qui l&#8217;avaient d&eacute;j&agrave; install&eacute; restent concern&eacute;es. Le c&eacute;l&egrave;bre d&eacute;veloppeur Jameson Lopp a expliqu&eacute;:<\/p><oembed url=\"https:\/\/twitter.com\/lopp\/status\/1067129907501826048?ref_src=twsrc%5Etfw\"><\/oembed><p><b>Traduction: Le repository &#8220;event-stream&#8221; de NPM a &eacute;t&eacute; compromis. Si vous l&#8217;utilisez dans un projet avec &#8220;copay-dash&#8221;, le logiciel malveillant volera toutes les cl&eacute;s priv&eacute;es qu&#8217;il pourra trouver.<\/b><br>\n___<br>\nJackson Palmer, l&rsquo;entrepreneur australien plus connu pour avoir cr&eacute;&eacute; la fameuse cryptomonnaie &#8220;blague&#8221; Dogecoin, a ajout&eacute;:<\/p><oembed url=\"https:\/\/twitter.com\/ummjackson\/status\/1067132600739721216?ref_src=twsrc%5Etfw\"><\/oembed><p><b>Traduction: &ldquo;C&rsquo;est l&rsquo;un des probl&egrave;mes majeurs des portefeuilles de cryptomonnaies bas&eacute;s sur JavaScript avec de fortes d&eacute;pendances en amont provenant de NPM. @BitPay faisait essentiellement confiance &agrave; tous les d&eacute;veloppeurs en amont pour ne jamais injecter de code malveillant dans leur portefeuille. @Dominictarr a laiss&eacute; l&#8217;attaquant y entrer, malheureusement&rdquo;.<\/b><\/p><p>Event-stream est t&eacute;l&eacute;charg&eacute; environ deux millions de fois par semaine par les programmeurs d&#8217;applications pour de nombreuses utilisations diff&eacute;rentes. La version contenant le programme malveillant, Event-Stream v 3.3.6, a &eacute;t&eacute; mise en ligne le 9 septembre via le r&eacute;f&eacute;rentiel Node Package Manager (NPM). Depuis, elle a &eacute;t&eacute; t&eacute;l&eacute;charg&eacute;e par pr&egrave;s de 8 millions de programmeurs d&#8217;applications.<\/p><p>Le code malveillant aurait tent&eacute; de voler des cryptos stock&eacute;es dans les portefeuilles Dash Copay Bitcoin &#8211; distribu&eacute;s via le NPM &#8211; et de les transf&eacute;rer sur un serveur situ&eacute; &agrave; Kuala Lumpur. Les responsables de NPM ont retir&eacute; la backdoor de la liste de NPM lundi dernier.<\/p>","protected":false},"excerpt":{"rendered":"<p>Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source Bitcoin de BitPay, aurait &eacute;t&eacute; compromis, ce qui est potentiellement aussi le cas pour d&rsquo;autres portefeuilles.Source: iStock\/NicoElNinoBitPay a publi&eacute; un avis indiquant que les versions de Copay 5.0.2 &agrave; 5.1.0 &eacute;taient affect&eacute;es par le code malveillant et [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6,1],"tags":[556,44,417,48,90],"editors":[2550],"sponsored_companies":[],"class_list":["post-31063","post","type-post","status-publish","format-standard","hentry","category-bitcoin-news","category-news","tag-applications","tag-bitcoin","tag-dogecoin","tag-piratage","tag-portefeuille","editors-jurgen-hoffman"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin<\/title>\n<meta name=\"description\" content=\"Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin\" \/>\n<meta property=\"og:description\" content=\"Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/\" \/>\n<meta property=\"og:site_name\" content=\"Cryptonews France\" \/>\n<meta property=\"article:published_time\" content=\"2018-11-27T14:15:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-26T11:07:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cimg.co\/news\/23880\/6153\/5bfd3810b16a0.jpg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin","description":"Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/","og_locale":"fr_FR","og_type":"article","og_title":"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin","og_description":"Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source","og_url":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/","og_site_name":"Cryptonews France","article_published_time":"2018-11-27T14:15:00+00:00","article_modified_time":"2023-06-26T11:07:31+00:00","og_image":[{"url":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin","twitter_image":"https:\/\/cimg.co\/news\/23880\/6153\/5bfd3810b16a0.jpg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/"},"author":{"name":"giedrius","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/person\/5d79e712f570715212460260f4f9cc0f"},"headline":"D\u00e9couverte d&#8217;une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin","datePublished":"2018-11-27T14:15:00+00:00","dateModified":"2023-06-26T11:07:31+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/"},"wordCount":690,"publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg","keywords":["Applications","Bitcoin","Dogecoin","Piratage","portefeuille"],"articleSection":["Actualit\u00e9s Bitcoin","News"],"inLanguage":"fr-FR","copyrightYear":"2018","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/","url":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/","name":"Mise en lumi\u00e8re d\u2019une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin","isPartOf":{"@id":"https:\/\/cryptonews.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#primaryimage"},"thumbnailUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg","datePublished":"2018-11-27T14:15:00+00:00","dateModified":"2023-06-26T11:07:31+00:00","description":"Un module appel&eacute; event-stream, utilis&eacute; par des millions d&rsquo;applications Web, et notamment dans Copay, le portefeuille open source","breadcrumb":{"@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#primaryimage","url":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg","contentUrl":"https:\/\/cimg.co\/w\/articles-attachments\/1\/5bf\/d380458867.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/fr\/news\/bitcoin-wallet-vulnerability-discovered-2400\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/fr\/"},{"@type":"ListItem","position":2,"name":"D\u00e9couverte d&#8217;une vuln\u00e9rabilit\u00e9 dans un portefeuille Bitcoin"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/fr\/#website","url":"https:\/\/cryptonews.com\/fr\/","name":"Cryptonews","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/fr\/#organization","name":"Cryptonews France","url":"https:\/\/cryptonews.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/3\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews France"},"image":{"@id":"https:\/\/cryptonews.com\/fr\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/31063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/comments?post=31063"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/posts\/31063\/revisions"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/media?parent=31063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/categories?post=31063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/tags?post=31063"},{"taxonomy":"editors","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/editors?post=31063"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/fr\/wp-json\/wp\/v2\/sponsored_companies?post=31063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}